CVE-2021-35036: Medium severity Zyxel AX7501-B0 firmware vulnerability
Published Mar 1, 2022
·Updated
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
Affected Software
64 affected components
Zyxel AX7501-B0 firmware<5.17\(abpc.2\)c0
Zyxel AX7501-B0
Zyxel DX3301-T0 firmware<5.50\(abvy.3\)c0
Zyxel DX3301-T0
Zyxel DX5401-B0 firmware<5.17\(abyo.2\)c0
Zyxel DX5401-B0
Zyxel Emg3525-t50b Firmware<5.50\(abpm.7\)c0
Zyxel Emg3525-t50b
Zyxel Emg5523-t50b Firmware<5.50\(abpm.7\)c0
Zyxel Emg5523-t50b
Zyxel Emg5723-t50k Firmware<5.50\(abom.8\)c0
Zyxel Emg5723-t50k
Zyxel Ep240p Firmware<5.40\(abvh.0\)c0a03
Zyxel Ep240p
Zyxel Ex5401-b0 Firmware<5.17\(abyo.2\)c0
Zyxel Ex5401-b0
Zyxel Ex5501-b0 Firmware<5.17\(abry.3\)c0
Zyxel Ex5501-b0
Zyxel Lte3301-plus Firmware<1.00\(abqu.6\)c0
Zyxel Lte3301-plus
Zyxel Lte5388-m804 Firmware<1.00\(abra.6\)c0
Zyxel Lte5388-m804
Zyxel Lte5388-s905 Firmware<1.00\(abvi.6\)c0
Zyxel Lte5388-s905
Zyxel Lte5398-m904 Firmware<1.00\(abqv.2\)c0
Zyxel Lte5398-m904
Zyxel Lte7240-m403 Firmware<2.00\(abmg.6\)c0
Zyxel Lte7240-m403
Zyxel Lte7461-m602 Firmware<2.00\(abqn.6\)c0
Zyxel Lte7461-m602
Zyxel Lte7480-m804 Firmware<1.00\(abra.6\)c0
Zyxel Lte7480-m804
Zyxel Lte7480-s905 Firmware<2.00\(abqt.6\)c0
Zyxel Lte7480-s905
Zyxel Lte7485-s905 Firmware<1.00\(abvn.6\)c0
Zyxel Lte7485-s905
Zyxel Lte7490-m804 Firmware<v1.00\(abqy.5\)c0
Zyxel Lte7490-m804
Zyxel Nr5101 Firmware<1.00\(abvc.6\)c0
Zyxel Nr5101
Zyxel NR7101 firmware<1.00\(abuv.7\)c0
Zyxel NR7101
Zyxel Nr7102 Firmware<1.00\(abyd.2\)c0
Zyxel Nr7102
Zyxel Pm7300-t0 Firmware<5.42\(acbc.1\)c0
Zyxel Pm7300-t0
Zyxel Pmg5317-t20b Firmware<5.40\(abki.4\)c0
Zyxel Pmg5317-t20b
Zyxel Pmg5617-t20b2 Firmware<5.41\(acbb.1\)c0
Zyxel Pmg5617-t20b2
Zyxel Pmg5617ga Firmware<5.40\(abna.2\)c0
Zyxel Pmg5617ga
Zyxel Pmg5622ga Firmware<5.40\(abnb.2\)c0
Zyxel Pmg5622ga
Zyxel VMG3625-T50B firmware<5.50\(abtl.0\)b2r
Zyxel VMG3625-T50B
Zyxel Vmg3927-t50k Firmware<5.50\(abom.8\)c0
Zyxel Vmg3927-t50k
Zyxel Vmg8623-t50b Firmware<5.50\(abpm.7\)c0
Zyxel Vmg8623-t50b
Zyxel VMG8825-T50K firmware<5.50\(abom.8\)c0
Zyxel VMG8825-T50K
Zyxel VMG3625-T50B firmware<5.50\(accr.0\)b4
Zyxel VMG3625-T50B firmware<5.50\(abpm.7\)c0
Event History
Mar 1, 2022
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-35036?
CVE-2021-35036 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2021-35036?
To fix CVE-2021-35036, update your Zyxel VMG3625-T50B firmware to the latest version provided by Zyxel.
3
What types of devices are affected by CVE-2021-35036?
CVE-2021-35036 primarily affects the Zyxel VMG3625-T50B firmware and other related Zyxel firmware versions.
4
What kind of data could be exposed due to CVE-2021-35036?
CVE-2021-35036 could expose sensitive information stored in the configuration file of the affected device.
5
Is there a workaround for CVE-2021-35036?
There is no official workaround for CVE-2021-35036, and the best course of action is to update the firmware.